5 ms·
Good thing nobody is silly enough to let fully autonomous AI agents run as regular users on these affected operating systems. That could be disastrous given a z
by jesse_dot_id 5mo ago
Good thing nobody is silly enough to let fully autonomous AI agents run as regular users on these affected operating systems. That could be disastrous given a zero day prompt injection technique.
- sieabahlpark 5mo ago[dead]
- chromacity 5mo agoI don't see what the issue is, my agent is already running as root.
- dnnddidiej 5mo agoYeah it has all the government logins and full gmail access. It will be too busy to bother rooting the local machine!
- latentsea 5mo agoShouldn't be a problem, we're currently clean on OpSec.
- pixel_popping 5mo agoAs it should for full yolo_O
- ryandrake 5mo agoGood thing we haven't normalized installing things with curl | sh
- dawnerd 5mo agoOr npm being allowed to run arbitrary post install scripts
- Semaphor 5mo agoI don’t think that matters as it’s usually curl | sudo sh
- FlyThruTheSun 5mo agoI literally ship an installer that runs with curl | bash... reading this thread while patching my servers is a fun experience lol
- still_grokking 5mo agoYeah, that's great! Imagine we would download random code from the internet and just execute it, like with NPM, PIP, Maven, Cargo etc.
- om8 5mo agocargo/uv/go have lock files though
- dnnddidiej 5mo agowith curl | sh you could use a checksum you download with curl!